Free
$0
- 3 hosts
- Manual scans
- Snapshot CVE feed (per release)
- Never expires
One paid plan. Fifty hosts, the daily CVE feed, and every feature Noxen has, for $12 a month. Three hosts are free forever - no card, no trial clock.
$0
$12 /month
Running more than 50 hosts, or managing client fleets? A multi-tenant MSP plan is in design and not yet on sale - we would rather say that than take money for a page of features. What is planned, and what exists today →
Side-by-side
What you get in each tier, in one row-per-feature view.
| Free | Noxen | |
|---|---|---|
| Price | $0 | $12/month, or $120/year |
| Host cap | 3 | 50 |
| Scheduled scans | Manual only | Nightly |
| CVE feed cadence | Per-release snapshot | Daily |
| Slack / Discord / Teams webhooks | - | Yes |
| SIEM export (Wazuh / Splunk / ELK / Loki) | - | Yes |
| Compliance mapping (CIS v8, SOC 2, ISO 27001) | - | Yes |
| Custom checks | - | Yes |
| Trial | n/a - the free tier does not expire | 30 days, full features, no card |
| Support | Community | Email, business-day reply |
Yes - $12/month, or $120/year, which works out at two months free. The CVE feed is rebuilt, re-indexed and re-signed every day, and that is a daily cost, so the price that pays for it recurs too. Cancel whenever you like: the app drops back to the free tier rather than stopping.
Fifty hosts instead of three, the daily CVE feed instead of the per-release snapshot, scheduled nightly scans, Slack / Discord / Teams webhooks, NDJSON SIEM export, CIS v8 / SOC 2 / ISO 27001 compliance mapping, and custom checks. There is one paid plan and it contains everything.
Yes - 30 days, every feature, no card. Thirty rather than fourteen because Noxen proves itself the morning a new CVE lands on a host you own, and a fortnight may not contain one. The free tier (3 hosts, manual scans, snapshot feed) is not time-limited.
It was retired. The old price list had a $79 one-time tier sitting next to a $19/month tier that bought four times the hosts and a better feed - the flagship option was the worst value on the page. One plan at $12/month replaces all of it. Nobody had bought the one-time licence, so nobody was moved off anything.
No. Noxen is agentless - it connects over SSH using a key you already have and reads package inventory, sshd_config, authorized_keys, and a few other inspection points. No agent to install, update, or worry about when a host is decommissioned.
No. Scan results live in your local SwiftData store on your Mac. Nothing is uploaded to Noxen servers - the only outbound traffic from the app is the signed CVE feed download and (if enabled) webhook deliveries to endpoints you configure. There is no shared dashboard URL, no public link, no telemetry on what you scan or find.
The App Sandbox blocks access to ~/.ssh/config
and raw sockets, both of which Noxen needs. Developer ID
notarisation gives us the same Gatekeeper trust model
without the sandbox limits.
More detail here.